

Firewalls Don't Stop Dragons Podcast
Carey Parker
A Podcast on Computer Security & Privacy for Non-Techies
Episodes
Mentioned books

Sep 15, 2025 • 1h 8min
On the Ethics of AI
Artificial Intelligence (AI) is the Big Tech buzzword of the day. Every company who wants investment (public or private) is scrambling to have an “AI story”, adding chatbots and ‘agentic’ features in their products wherever possible. The AI companies themselves are constantly expanding their models, ingesting as much data (including highly personal information) as possible. In this AI gold rush, companies are making flawed and often harmful products. Companies are firing workers and trying to replace them with AI bots. And it’s forcing us all to question what’s real, what has actual value, and what the impacts could and should be on society as a whole. Discussing deep questions like this is the purview of philosophers – and today I’ll be welcoming back someone uniquely and supremely qualified to address them, Carissa Véliz.
Interview Notes
Carissa Véliz: https://www.carissaveliz.com/
Privacy is Power: https://www.carissaveliz.com/books
Carissa’s research: https://www.carissaveliz.com/research
Moral Zombies: https://link.springer.com/article/10.1007/s00146-021-01189-x
ChatGPT suicide: https://www.nytimes.com/2025/08/26/technology/chatgpt-openai-suicide.html
TESCREAL: https://en.wikipedia.org/wiki/TESCREAL
John Oliver on AI Slop: https://www.youtube.com/watch?v=TWpg1RmzAbc
Proton Lumo: https://proton.me/blog/lumo-ai
EU’s “public good” LLM: https://ethz.ch/en/news-and-events/eth-news/news/2025/07/a-language-model-built-for-the-public-good.html
Further Info
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support the mission: https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Table of Contents
0:00:00: Intro
0:05:09: What does “artifical intelligence” really mean?
0:13:21: Should STEM degrees require ethics training?
0:17:20: Does anthropomorphising AI undermine our discourse?
0:22:35: What is the TESCREAL view of AI?
0:28:09: Can we infuse AI tools with human morality?
0:34:31: What are the dangers of training AI on copyrighted works?
0:42:16: What happens when AI starts ingesting it’s own output?
0:44:27: Can we make AI systems that are truly private?
0:48:08: How should we assign liability for AI harms?
0:51:06: Is AI eroding our ability to trust anything?
0:54:06: What happens when AI obviates the need to work at all?
1:00:00: How do we maximize the benefits and minimize the harms of AI?
1:03:20: Interview wrap-up
1:06:06: Patron podcast preview
1:07:08: Looking ahead

Sep 8, 2025 • 1h 3min
Find Old Accounts (Part 1)
Delve into the world of online security as the discussion kicks off with the importance of using password managers to track all your accounts, including those long-forgotten. Explore alarming trends like Android malware spreading through Facebook ads and critical Google updates that affect app security. There's a spotlight on ethical concerns surrounding AI and the need for parental controls. Finally, uncover ways to minimize your digital footprint while navigating the complexities of privacy regulations and ensuring your data remains secure.

Sep 1, 2025 • 1h 6min
Meet Rayhunter
Join Cooper Quintin, security researcher at EFF, and The Gibson, founder of Hackers.Town, as they dive into the Rayhunter project, a groundbreaking tool aimed at detecting cellular surveillance. They discuss how our phones inadvertently broadcast our locations and the threats posed by cell site simulators. The conversation highlights privacy activism, the evolution of surveillance technologies, and practical steps individuals can take to protect their digital privacy. This engaging dialogue sheds light on the intersection of technology, activism, and community efforts.

Aug 25, 2025 • 1h 6min
Going on a Data Diet
Dive into the digital world as the hosts dissect the risks of online accounts and the concept of a 'data diet' to enhance your privacy. Learn about critical security flaws in Dell laptops and the potential privacy breaches with Meta scanning your photos. The discussion also highlights the struggles with data brokers and the impacts of the new EU chat control law. Plus, uncover the truth about car theft myths linked to privacy technology, and navigate the alarming vulnerabilities found in controversial dating apps.

6 snips
Aug 18, 2025 • 1h 12min
I’m Just a (Privacy) Bill
Monique Priestley, a Vermont State Representative and consumer protection advocate, shares her experiences navigating the complex world of privacy legislation. She reveals the hurdles faced in passing the Vermont Data Privacy Act and the strategies used against powerful Big Tech lobbyists. Discover the importance of collaboration among legislators, challenges of balancing privacy rights with corporate protection, and lessons learned for future advocacy efforts. Monique sheds light on the need for transparency and citizen involvement in shaping meaningful privacy laws.

Aug 11, 2025 • 58min
Hacker Summer Camp 2025
It’s early August, which means it’s time for BSides Las Vegas and DEF CON, part of the trio of conferences that make up “hacker summer camp” (the other being Black Hat, which I don’t attend). It’s been a crazy, chaotic week – as usual – but in almost completely good ways. After the regular news, I’ve got some mini interviews with Jake Braun (DEF CON Franklin), Stacey Higginbotham (Consumer Reports), Cooper Quitin (EFF) and The Gibson (Veilid and hackers.town).
In other news: Tea app users file a class action lawsuit over massive breach; ChatGPT sessions may be searchable by anyone; US government launches initiative to centralize health data for use by tech companies; Australia rolls out age verification for search engines; Grok AI is now in Teslas; China-backed hackers exploit horrific Microsoft bug; Dropbox ends its password manager service.
Article Links
Tea User Files Class Action After Women’s Safety App Exposes Data https://www.404media.co/tea-user-files-class-action-after-womens-safety-app-exposes-data/
ChatGPT users shocked to learn their chats were in Google search results https://arstechnica.com/tech-policy/2025/08/chatgpt-users-shocked-to-learn-their-chats-were-in-google-search-results/
Trump administration is launching a new private health tracking system with Big Tech’s help https://apnews.com/article/trump-ai-rfk-jr-health-tech-fa73703bd1fd557c787ef0b590e151f1
Australia is quietly rolling out age checks for search engines like Google https://www.abc.net.au/news/2025-07-11/age-verification-search-engines/105516256
Grok is now in Tesla cars, but not in the way you think https://mashable.com/article/grok-tesla
China-backed hackers used Microsoft flaw in attacks https://www.washingtonpost.com/technology/2025/07/21/china-hackers-microsoft-sharepoint/
Users left scrambling for a plan B as Dropbox drops Dropbox Passwords https://www.theregister.com/2025/07/30/dropbox_drops_dropbox_passwords/
Tip of the Week: https://firewallsdontstopdragons.com/how-to-backup-cloud-data/
Further Info
Top hacker interviews: https://fdsd.me/hackers
DEF CON Franklin: https://defconfranklin.com/
EFF: https://www.eff.org/
Veilid: https://veilid.com/
Consumer Reports: https://securityplanner.consumerreports.org/
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support our mission! https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Table of Contents
0:00:00: Intro
0:02:24: News preview
0:03:31: Tea User Files Class Action Lawsuit
0:06:24: ChatGPT users shocked to learn their chats were in Google search results
0:11:11: Trump administration is launching a new private health tracking system
0:17:52: Australia is quietly rolling out age checks for search engines
0:22:56: Grok is now in Tesla cars, but not in the way you think
0:25:29: China-backed hackers used Microsoft flaw in attacks
0:29:50: Dropbox drops Dropbox Passwords
0:32:20: Tip of the Week
0:36:27: Hacker Summer Camp Extras!
0:42:53: SNIPPET: Stacey Higginbotham
0:47:03: SNIPPET: Jack Braun
0:50:18: SNIPPET: Cooper Quintin and Gibson
0:55:04: Wrapup

Aug 4, 2025 • 1h 2min
Tariffs vs IP Law
Cory Doctorow has garnered a lot of needed attention to the decline of modern online platforms, including Google Search, Facebook and Twitter. Much of this is a result of coining the now-viral term Enshittification. Today we’ll talk about how the internet was broken and who’s to blame. We’ll also discuss the lack of privacy laws and the threats of AI to tech workers and copyrighted works. Finally, we’ll discuss Cory’s novel proposal for how countries could respond to US tariffs by ripping up intellectual property agreements, changing the power dynamic of the Big Tech industry and hopefully benefiting consumers in the process.
Interview Notes
Cory’s blog (Pluralistic): https://pluralistic.net/
Canada shouldn’t retaliate with US tariffs: https://pluralistic.net/2025/01/15/beauty-eh/#its-the-only-war-the-yankees-lost-except-for-vietnam-and-also-the-alamo-and-the-bay-of-ham
Who Broke the Internet? https://www.cbc.ca/listen/cbc-podcasts/1353-the-naked-emperor
Enshittification book (coming Oct 2025): https://us.macmillan.com/books/9780374619329/enshittification/
Regex: https://en.wikipedia.org/wiki/Regular_expression
Copyright and AI: https://www.technologyreview.com/2025/07/01/1119486/ai-copyright-meta-anthropic/
Further Info
Humble Bundle: https://www.humblebundle.com/books/security-apress-books
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support the mission: https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Table of Contents
0:00:00: Intro
0:02:07: Humble Bundle!
0:03:09: Interview preview
0:06:52: Has coining the term Enshittification helped to raise awareness?
0:11:08: Who broke the internet?
0:20:15: Will AI reduce tech workers’ power?
0:27:21: Why can we not get privacy laws?
0:35:21: How should countries respond to US tariffs?
0:39:57: Do DRM protections incentize creators?
0:44:37: What’s your take on the Anthropic AI copyright decision?
0:55:03: What’s next for you?
0:56:04: Interview wrap-up
0:57:27: Hacker summer camp
0:59:28: Patron podcast preview
1:00:24: Looking ahead

Jul 28, 2025 • 1h 19min
Physical Phone Security
Explore how our phones, essential in daily life, can compromise personal data if physically accessed. Discover new iOS and Android features that bolster your phone’s security. Learn about the surge in VPN usage in the UK spurred by privacy concerns following new regulations. Dive into the ethics of data privacy in dating apps and examine ways to minimize your digital footprint amidst rising surveillance. Also, gain insights on AI's role in privacy and the importance of making informed choices for protecting your personal information.

Jul 21, 2025 • 1h 10min
Passport, Lawyer, Locksmith
We talk a lot about digital or online security. Today we’re going to focus on physical security and the general ethos of “be prepared”. There are many situations in life when you will find yourself wishing you had had the foresight to acquire certain things or establish certain professional relationships before you actually needed them. Deviant Ollam is a physical penetration specialist. His job is to find and fix weaknesses in physical things… buildings, locks, safes, etc. And along the way he has learned some important lessons for all of us. Today he will share his wisdom with us.
Interview Notes
Deviant’s website: https://deviating.net/
Lawyer,Passport, Locksmith, Gun talk: https://www.youtube.com/watch?v=6ihrGNGesfI
Attacking Classified Safes & Vaults: https://www.youtube.com/watch?v=-Z_Jv7vuiqg
Red Team Alliance: https://shop.redteamalliance.com/
Red Team Tools: https://www.redteamtools.com/
CackalackyCon: https://www.cackalackycon.org/
Shut the F**k Up PSA: https://www.youtube.com/watch?v=nWEpW6KOZDs
Home lock – Schlage Primus: https://commercial.schlage.com/en/products/key-systems/primus-security-upgrade.html
Padlock – Pacific Lock (PACLOCK): https://paclock.com/
Further Info
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support the mission: https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Table of Contents
0:00:00: Intro
0:04:27: What is a physical entry specialist?
0:08:47: How would you describe the prepper ethos?
0:12:21: What are common mistakes for disaster prep?
0:15:52: What should everyone have a passport?
0:20:32: Why should everyone have an established lawyer?
0:28:55: What other professionals should I have at the ready?
0:34:09: What locks should I use or avoid?
0:40:39: Do any movies and TV shows portray lock picking correctly?
0:43:36: What is ‘responsible disclosure’ like for physical vulnerabilities?
0:47:44: Do you tell companies when you stumble on physical vulnerabilities?
0:51:41: What documents should we have physical copies of?
0:55:27: If I’m politically active, how can I minimize my digital footprint?
0:59:10: Why should we use secure, private communications?
1:02:34: What’s next for you?
1:06:05: Wrap-up
1:08:45: Patron podcast preview

Jul 14, 2025 • 1h 4min
Freezing Your Mobile Account
Your cell phone number uniquely identifies you. Many companies rely on this 1-to-1 relationship to authenticate you to their systems. So if someone were to somehow manage to steal your mobile phone number – a hack called SIM swapping – they could use that to impersonate you and compromise any of your accounts that are validated via SMS or phone call. There’s a new tool to combat this scam that’s better than the old-style account PIN codes. I’ll explain how it works.
In the news: many Brother printers have serious cyber vulnerabilities; Belkin in abandoning Wemo smart devices next January; Xfinity’s WiFi routers can detect motion in your entire home; Bluesky is rolling out age verification in the UK; California is using drones to catch the use of illegal fireworks; McDonald’s AI hiring bot was hacked to expose millions of applicants’ data; Mexican drug cartel hacked FBI phone to catch informants; US strikes blow against North Korean fake worker scams; Denmark is looking to ditch Microsoft products.
Article Links
New Vulnerabilities Expose Millions of Brother Printers to Hacking https://www.securityweek.com/new-vulnerabilities-expose-millions-of-brother-printers-to-hacking/
Belkin pulls the plug on Wemo smart home products which will stop working in 2026 https://9to5google.com/2025/07/10/belkin-wemo-smart-home-shutdown-list/
Using WiFi Motion in the Xfinity app https://www.xfinity.com/support/articles/wifi-motion
Bluesky is rolling out age verification in the UK https://www.theverge.com/news/704468/bluesky-age-verification-uk-online-safety-act
Huge fines coming for Californians caught by drone with illegal fireworks https://www.sfgate.com/bayarea/article/california-drones-illegal-fireworks-20629637.php
McDonald’s AI Hiring Bot Exposed Millions of Applicants’ Data https://www.wired.com/story/mcdonalds-ai-hiring-chat-bot-paradoxai/
Drug cartel hacked FBI official’s phone to track and kill informants https://arstechnica.com/security/2025/06/mexican-drug-cartel-hacked-fbi-officials-phone-to-track-informant-report-says/
Identities of More Than 80 Americans Stolen for North Korean IT Worker Scams https://www.wired.com/story/identities-of-80-plus-americans-stolen-for-north-korean-it-worker-scams/
Why Denmark is dumping Microsoft Office and Windows for LibreOffice and Linux https://www.zdnet.com/article/why-denmark-is-dumping-microsoft-office-and-windows-for-libreoffice-and-linux/
Tip of the Week: https://firewallsdontstopdragons.com/freezing-your-mobile-account/
Further Info
Tom’s Hardware on WiFi Motion: https://www.tomshardware.com/networking/routers/new-xfinity-router-motion-detecting-feature-stokes-privacy-fears-feature-powered-by-wi-fi-signals
RockYou password list: https://cybernews.com/security/rockyou2024-largest-password-compilation-leak/
LibreOffice: https://www.libreoffice.org/discover/libreoffice/
Eurostack: https://eurostack.eu/
Running Linux in a VM on Windows: https://itsfoss.com/install-linux-mint-in-virtualbox/
Age verification: https://www.privacyguides.org/articles/2025/05/06/age-verification-wants-your-face/
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support our mission! https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Table of Contents
0:00:00: Intro
0:00:17: DEF CON coming up fast
0:03:34: News preview
0:06:31: New Vulnerabilities Expose Millions of Brother Printers to Hacking
0:11:51: Belkin pulls the plug on Wemo smart home products
0:14:25: Using WiFi Motion in the Xfinity app
0:21:19: Bluesky is rolling out age verification in the UK
0:26:49: Huge fines coming for Californians caught by drone with illegal fireworks
0:29:36: McDonald’s AI Hiring Bot Exposed Millions of Applicants’ Data
0:35:31: Drug cartel hacked FBI official’s phone to track and kill informants
0:39:54: Identities of More Than 80 Americans Stolen for North Korean IT Worker Scams
0:48:33: Why Denmark is dumping Microsoft Office and Windows for LibreOffice and Linux
0:55:48: Tip of the Week
1:01:37: Merch reminder
1:02:12: Patron podcast preview
1:02:45: Looking ahead